high · CVSS v3 7.5 · EPSS 0.00136
CVE-2026-87839
The Tripzzy WordPress plugin (v<1.5.1) lacks authorization checks on an AJAX endpoint, letting unauthenticated users delete any comment. Thi
Overview
The Tripzzy WordPress plugin (v<1.5.1) lacks authorization checks on an AJAX endpoint, letting unauthenticated users delete any comment. This flaw can erase user-generated content and disrupt site integrity. It is a high‑severity vulnerability that can be exploited without credentials.
Description
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
Impact
Confidentiality: comment data can be removed, affecting content integrity. Integrity: arbitrary comments can be deleted, undermining trust. Availability: repeated deletions could degrade user experience. Site administrators and users are impacted.
Remediation
Update the Tripzzy plugin to version 1.5.1 or later. If update not possible, disable the AJAX endpoint or remove the plugin. Monitor comment logs for unexpected deletions and restore from backups if necessary.
Risk context
Severity is high with CVSS 7.5 and EPSS 0.00136, indicating a low probability but significant impact. Defenders should treat it as a moderate to high priority patch.
Affected products
- Tripzzy plugin
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- 0.00136